feat: add server, workstation, and cloud edition manifests

Define the three flagship editions as plain-text manifests:

- server (bastion): production server - observability stack, containers.
- workstation (forge): curated KDE Plasma + dev toolchains.
- cloud (nimbus): cloud kernel, cloud-init, guest agents.

Each manifest carries metadata (services to enable/mask), a package
list, a hardened kernel cmdline, and a btrfs fstab template.
This commit is contained in:
Blake Ridgway
2026-08-21 13:15:43 -05:00
parent 14e5ea9e1e
commit 729f191950
12 changed files with 463 additions and 0 deletions

View File

@@ -0,0 +1,35 @@
# Arcline Server — kernel command line
# Hardening flags + console config. Kept explicit and auditable.
#
# Security notes:
# init_on_alloc / init_on_free — zero freshly allocated/freed memory
# slab_nomerge — disable merging of similar slab objects
# page_poison=1 — fill freed pages to catch use-after-free
# pti=on — kernel page-table isolation
# spectre_v2=on spec_store_bypass=on — mitigations on (no auto-off)
# tsx=off — disable TSX (TAA mitigations)
# lockdown=integrity — block unsigned kernel modifications
# oops=panic panic=-1 — panic (and stay down) on oops
# quiet loglevel=3 — quiet serial console boot
console=tty0
console=ttyS0,115200n8
quiet
loglevel=3
systemd.show_status=auto
# hardening
init_on_alloc=1
init_on_free=1
slab_nomerge
page_poison=1
pti=on
spectre_v2=on
spec_store_bypass=on
tsx=off
lockdown=integrity
oops=panic
panic=-1
# btrfs / storage
rootflags=subvol=@